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Abstract 

Social Security and other public policies can be viewed as a series of cash in and 
outflows that depend on parameters such as the age distribution of the population and 
the retirement age. Given forecasts of these parameters, policies can be designed to be 
financially stable, i.e., to terminate with a zero balance. If reality deviates from the 
forecasts, policies normally terminate with a surplus or a deficit. Wc derive constraints 
on the cashflows of robust policies that terminate with zero balance even in the presence 
of forecasting errors. Social Security and most similar policies are not robust. We 
show that non-trivial robust policies exist and provide a recipe for constructing robust 
extensions of non-robust policies. An example illustrates our results. 



1 Introduction 



Social Security is running into financial difficulty, public and private pension funds are 
chronically underfunded, and many public policies cost the tax payer much more than 
anticipated. What is the reason for this unfortunate track record? Is it poor management? 
Is it faulty policy design? Or is it perhaps unavoidable that public policies turn into financial 
problems? 

Entitlement programs and other public policies generally function by redistributing 
money. They collect taxes from one group and make payments to another in order to 
accomplish some social objective. A well-designed policy should cover its cost. The sum 
of all cash inflows should be sufficient to cover the sum of all payments so that the policy 
terminates with a zero balance rather than a deficit or surplus. We will refer to such policies 
as stable policies. 

To design a stable policy, it is necessary to forecast the parameters that determine the 
cashflows over the life of the policy. For Social Security these parameters include the average 
life expectancy, the demographic composition of the population, etc. With these forecasts 
in hand, the designer can set the level of taxation and benefit payments to ensure that the 
policy covers its cost. 

The example of Social Security shows that a stable policy can still run into financial 
difficulties if reality differs from the forecasts used to design it. Actual cashflows depend 
on the parameters observed in the real world, not on the forecast values used to design 
the policy. This is the reason why Social Security is accumulating an ever-growing deficit. 
People live longer than forecast and the ratio of people paying in to people drawing benefits 
is lower than expected. 

Even the best forecasts will differ from observed reality. Furthermore, the difference 
between the forecast and the observed reality generally increases with the age of the forecast. 
See Refs. [1] and [2] for examples. Since such forecasting errors are unavoidable, a good 
policy should not only be stable, it should forgive forecasting errors. A robust policy will still 
terminate with a zero balance even if reality differs from the forecast by a small amount 1 . 

In this paper we derive model-independent constraints on the cashflows of robust poli- 
cies. We show that robust polices must have cashflows that depend not only on parameters 
but also on their rate of change. This allows such policies to adapt to small unanticipated 
changes in the parameters that determine the cashflows. We also briefly discuss a class of 
super robust policies that can adapt to arbitrarily large forecasting errors. 

The cashflows of most current policies depend only on parameters, but not on their rate 
of change. These policies cannot be robust. This is part of the reason why entitlement 
programs tend to run into financial difficulties. We provide a recipe for constructing robust 
extensions of such non-robust policies to show that such extensions always exist. 

In practice, it is very difficult to generate forecasts for the parameters that determine 
the policy cashflows. Ref. [4] presents a detailed model that relates the forecasts for some 
twenty- two parameters, ranging from tax rates to government debt and the value assigned 
to leisure time, to future Social Security contributions and payments. This model is very 
complex in part because it attempts to capture human behaviors such as the decision when 
to retire. These decisions in turn determine the cashflows into and out of the Social Security 

x Our terminology is similar to the usage in Robust Control Theory. See, for example, [3]. 



1 



trust fund. Modeling human behavior requires modeling subjective judgments, for example 
the importance of leisure time. These quantities are difficult to measure directly. 

For our analysis, we assume that the cashflows are determined by directly measurable 
quantities and that forecasts for these quantities are available. For example, we would think 
of cash outflows from Social Security in terms of the number of retired people, a quantity 
can easily be measured and compared to a forecast. This model-independent approach 
allows us to avoid the complexities of generating forecasts and enables us to make general 
statements about the parameter dependence of policy cashflows. 

In the next section we define the mathematical framework for this discussion. The 
following two sections discuss the general properties of robust policies and show that current 
policy design generally yields non-robust policies. Section 5 introduces simple examples of 
robust and super-robust policies. In Section 6 we show that it is always possible to find a 
robust extension of a non-robust policy. Sections 7 and 8 illustrate the results from earlier 
sections by applying them to a simple example. We conclude in section 9 with a summary 
and some remarks. 

2 Definitions 

The net value of the policy at time t is the sum of the cash in and outflows, Cj and c , from 
inception of the policy at t' = to t! = t: 



For simplicity, we calculate the future value of the cashflows assuming that both sur- 
pluses and deficits grow at a fixed rate r. The definition of V(t) ensures that V(0) = 0, i.e., 
the policy begins without preexisting assets or liabilities. It then accumulates net assets or 
liabilities as time progresses. 

The value of the policy depends on the difference between cash in and outflows. The 
constraints we derive in this paper only apply to this net cashflow, leaving it up to the policy 
designer to determine the split between cash in and outflows. In practical terms, a policy 
designer would probably start from the desired payout, c D , to accomplish the policy goal, 
and construct a Cj such that the robustness constraints on the net cashflow are satisfied. 

The cashflows q/ D are functions of t' and depend on one or more parameter functions. 
For entitlement programs these parameter functions could include the life expectancy, the 
percentage of people receiving benefits, and similar quantities. 

In this framework, a stable policy (as defined in the introduction) terminates at time T 
with a zero balance, V(T) = 0, assuming that reality matches the forecast. A robust policy 
terminates with V(T) = even if there are small differences between the observed values 
and the forecast. A super robust policy terminates at V(T) = no matter how much reality 
differs from the forecast. 

This discussion requires two versions of each of the parameter functions, the forecast 
and the observed values. We use pk, where k enumerates the parameter functions, for 
the forecasts that are available at inception of the policy. A policy designer determines 
the parameter dependence of the cashflows Cj/ using these forecasts, because the observed 
values values are not yet known. 




(1) 
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When the policy is implemented, the parameter dependence of the cashflows remains 
fixed, but their values are determined by the observed parameter functions, rather than the 
forecasts. We will use pk for the observed values corresponding to the forecasts p^- The 
observed values determine the value of the real-world policy cashflows. 

The focus of this paper is to derive constraints on robust policy design. At design time, 
the policy designer only knows the forecasts and that reality will differ in some unknown 
way from these forecasts. The next few sections discuss constraints that can be derived 
using this knowledge. 

Policy cashflows can depend on the pk at various points in time. For example, Social 
Security payouts may depend on demographic data (life expectancy, population size, etc) 
at some earlier time. Define a generalized parameter function to use in policy design as 



where is a functional of the parameter p\. and is a weight function. The observed 
qk, calculated from the pk, determine the actual cashflows. The definition of the q^ ensures 
that they depend only on values of pk that are known at time t'. 

Armed with these generalized parameter functions, we can now introduce a convenient 
notation for the adjusted net cashflows 2 in Eq. (1): 



The cashflows are a function of the generalized parameter functions qk(t r ), their rate of 
change, and if . This defines a fairly general class of cashflows that includes many current 
policies as well as a wide range of non-trivial robust examples. 

We have made a two simplifying assumptions. Q can depend on higher time derivatives 
of <7fc. Including them would add flexibility for real policy design, but it would complicate 
the presentation here without adding anything qualitatively new. 

A more important simplification is our assumption that there is a one-to-one correspon- 
dence between the observable parameters pk and the generalized parameters q^ . Many real 
policies fall into this category, but more general cashflows can depend on different averages 
of the same parameter function. We do not consider this situation in this paper. 

3 From Stability to Robustness 

Given pk, a policy designer can construct qk and Q so that the policy terminates with a net 
zero balance and accomplishes the policy goals. The resulting policy is stable by design. 

In reality, the policy cashflows depend on the observed values of the parameters, pk, 
which normally differ from the forecasts. Replacing the forecast with the observed values 
can be viewed as a variation of the parameter functions, p^: 




(2) 



Q(qk,qk,t') = (ci-c )e r(T - t ' ) . 



(3) 



Pk -> Pk = Pk + $Pk- 



(4) 



2 A dot over a function of time represents its time derivative. 
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Here 5p k is the forecasting error. The forecasting error is non-zero only for t" > 0. For 
t" < 0, the observed reality is known at design time, so p k = p k - We assume the 5pk are 
small and work to first order in these small quantities. 

Varying pk causes the generalized parameter functions to change as q k — > q k = Qk + Sq k , 
where 3 

Sqk = f dt" dFk{p f' )X) 5p k (t")g k (t\ t") + 0(5p 2 ). (5) 

J-oo OPk 

Similarly, for cashflows that depend only on q k , q k and t', we find Q — > Q + SQ with 

This finally lets us compute the change in the terminal value of the policy as we replace the 
forecast parameter function with the observed one: 

5V = ( T dt'Y, (f^9k + f^%) +0(5q 2 ). (7) 
Integrating by parts, we find 

rT /QQ d QQ\ QQ 



Jo ^ \oq k dt'dq k J dq k t'=T 



where the boundary term reflects that in general the 5q k (T) are not equal to zero. 

A robust policy must have SV = 0, i.e., its terminal value must remain unchanged if 
reality differs from the forecast. Policies are robust (at leading order) if the net cashflows 
satisfy the following Euler-Lagrange equation 4 and boundary condition: 



(9Q_d L dQ\ =0and ^Q_ 

\dq k dt'dq k J dq k 



= 0. (9) 

t'=T v ' 



For this derivation we did not need to know the values of 5p or 5q. We simply assumed 
that we have a non-zero forecasting error and that it is small enough to neglect higher order 
terms. Eq.(9) provides a constraint on the functional form of the net cashflows Q in terms 
of the forecasts q k available at design time. If the constraint is satisfied, the resulting policy 
will terminate with balanced books in the presence of small forecasting errors. 



4 Policies Without Time Derivatives Cannot Be Robust 

The somewhat abstract constraint in Eq. (9) has far-reaching consequences for policy design. 
In this section we show that a broad class of policies that includes Social Security cannot 
be robust. 

The cashflows into and out of the Social Security fund depend only on the generalized 
parameter functions q k , but not on their rate of change. For example, the inflows depend 

3 We assume that the relation between q k and p k is such that there exist a 8p k that can produce an 
arbitrary variation in q k . 
4 See, for example, [5]. 
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on the number of people making payments and how much they earn. They do not depend 
on how these quantities have changed. Similarly, the payouts depend on the number of 
recipients and how much they paid in while they were working. Again, the rate of change 
of these quantities has no bearing on the payments. 

Most current policies follow the same pattern. The cashflows depend on the generalized 
parameters q^, but not on their time derivatives q^. For this type of policy Q = Q(qk,t')- 
Evaluating the constraint, Eq. (9), for cashflows with this functional form we find 

|^=0. (10) 

Non-trivial Q that satisfy this constraint exist. For these cashflows, the leading order 
contributions to 5Q and SV are of order Sq 2 or higher. Such policies achieve robustness 
by being approximately independent of q^. Cashflows of the form Q = f(t r ) are exactly 
independent of q^. The special case Q = 0, defines a Pay-As-You-Go policy for which the 
in and outflows net to zero at every point in time. 

We conclude that there are no robust policies of the form Q = Q(qk,t') with non-trivial 
q^-dependance at leading order. 

Most real-world policies depend on parameters. For example, a useful unemployment 
insurance should build up assets during times of full employment and pay them out when 
unemployment is high. To accomplish this, the net cashflow must be a function of the 
unemployment rate, i.e. dQ/dq ^ 0, violating the constraint Eq. (10). Social Security, 
defined benefit pension plans, and similar policies also have net cashflows that depend on 
parameters and therefore violate Eq. (10). Because the constraint is not satisfied, these 
policies cannot be robust. 

A policy that is exactly or approximately independent of the unemployment rate often 
fails to accomplish the policy goals. For example, a Pay-As- You-Go version of the unem- 
ployment insurance would either raise rates for people with jobs when unemployment is high 
to to cover payments to the unemployed or lower benefits to match the reduced inflows. 
A more general policy with Q = f(t') would accumulate assets at a predefined time and 
have net outflows at other predefined times. Neither solution accomplishes the policy goal 
of mitigating the effect of economic cycles on the workforce. 

In the introduction we asked why so many policies run into financial difficulties. Now 
we see that many policies are intrinsically unstable with respect to forecasting errors. This 
is a general result that only depends on the functional form of the net cashflows, not on any 
policy specific details. In order to construct non-trivial robust policies, the net cashflows 
must depend on time derivatives of the parameter functions. 



5 Non- Trivial Robust Policies 

In the previous section we saw that it is impossible to construct non-trivial robust policies 
with cashflows of the form Q(qk,t'). The cashflows had to be at least approximately inde- 
pendent of qk to satisfy the robustness constraint. In this section we show how to construct 
robust policies with non-trivial qk dependence. 

The easiest way to satisfy Eq. (9) is to define Q as a total time derivative of another 
function. A simple choice, L(qk,t'), yields 
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„, dL dL t—^ dL . 



with the boundary condition 

dL 



= 0. (12) 

t'=T y ' 



Any non-trivial L that satisfies this boundary condition yields a robust policy with 
cashflows that depend on parameter functions. 

Policies with cashflows that are given by total time derivatives are especially tractable, 
because we can calculate the terminal value of the policy without knowing the functional 
form of L: 

V(T)= [ T dt'Q = L(q k ,t') T (13) 
Jo 

The boundary condition Eq. (12) ensures that the variation of V vanishes at linear order 
in Sq: 

8T 

By tightening the boundary condition on L to require all derivatives to vanish at t' = T, 

d n L 
~dq» 

we can identify a class of policies for which SV vanishes to all orders in Sq. These policies 
are guaranteed to terminate with V(T) = no matter how much reality differs from the 
forecast. They are super-robust. 

It is straightforward to construct examples of super-robust policies. The ansatz below 
defines the cashflows in terms of an arbitrary function M in a way that ensures that the 
condition for super-robustness, Eq. (15), is satisfied. 

Q(qk,q k ,t') = ~ [(T-t>)M(q k (t>),t>)]+C(t>) (16) 
With this ansatz, the terminal value of the policy is given by 

V(T) = -M(q k (0), 0) + j T dt'C(t'). (17) 

Jo 

V(T) only depends on the value of q k at inception, which is known when the policy is 
designed. C{t') can be chosen to make V(T) = 0. 

The results in this section show that it is mathematically very simple to construct robust 
and super-robust policies. However, a purely mathematical solution is likely to be of limited 
use for real-world applications that normally start from a policy goal rather than a desire 
to satisfy Eq. (9). The next section discusses ways to design robust policies based on more 
practical starting points. 
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6 Robust Extensions of Non-Robust Policies 



In Section 4 we showed that most current policies are not robust, which contributes to the 
solvency problems many of them encounter. This section provides a recipe for constructing 
a robust extension of a non-robust policy. For simplicity we consider policies that depend 
on only one parameter. 

We take the simplest approach possible to show that a robust extension always exists. 
This is one of infinitely many robust extensions to a given non-robust starting point. For 
real- world applications, the policy designer needs to find an extension that keeps the original 
policy goal intact without placing an undue burden on the population that is paying for it. 

Many existing policies are defined in terms of cashflows that depend on just the pa- 
rameter function q, but not its time derivative. We can extend a non-robust policy Q(q,t') 
by adding a correction term that allows us to satisfy the constraint Eq. (9). The simplest 
expression that leads to a robust policy is 

Q(q, q, = Q(q, + A(t')q + C(f ) . (18) 

Inserting this ansatz into the Euler-Lagrange equation, Eq. (9), the boundary condition 
becomes A(T) = and we find 

dQ = d_A 

dq df " 1 j 

This equation determines the time dependence of A. We emphasize that A is a function of 
time only. It is set once at design time using the explicit time dependence of the forecast q 
and does not change over the life of the policy. C can be chosen arbitrarily subject to the 
constraint that our modified policy should terminate with V(T) = 0. 

For a given Q these equations always produce a robust policy. This robust policy is 
one of infinitely many ways to extend the non-robust starting point. Practical applications 
would most likely require a more flexible ansatz. 

7 Toy Social Security Policy 

A very simplified (i.e., toy) Social Security policy illustrates the concepts discussed in the 
preceding sections. In this toy model, retirees receive a fixed payment, c ou t, and everybody 
else makes a fixed contribution, Cj n . p(t') is the forecast for the percentage of the population 
receiving benefits. We also assume that the total population is constant. Setting q(t') = 
p(t'), this gives us the following forecast value of the policy: 

V(t) = /V(c in (l -p(tO) - Cnap^yW. (20) 
Jo 

This is the Pay-As- You-Go solution where inflows equal outflows and the policy satisfies 
Q = for all f, if 

p(t') = (21) 

T '-'out 

This makes p a constant, independent of time. 
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The observed percentage of retired persons, p = p + Sp, differs from the forecast by 
a forecasting error Sp. To make the example explicit, we assume that 5p = et' , where e 
is a positive constant indicating that there is a higher percentage of retired people than 
expected at design time. 

The actual value of the policy depends on the observed percentage of people in retire- 
ment: 

V{t) = fdt\c in (l -p{t')) ~ CoutPit'W^. (22) 
Jo 

Using our forecast, Eq. (21), and the explicit form of the forecasting error we find 



Cin ~T C, 



V {t) = - e ~ m 1 ; out e rt -l-rt = ' i 1 + 0(r), (23) 



r 



t{ c in + C-out) ,2 



2 



which is negative and increases in magnitude with time. 

According to our definition of robustness, V must remain unchanged to linear order in 
the presence of forecasting errors. The result above is linear in the forecasting error. Clearly 
this toy model is not robust. 

8 Rendering the Toy Social Security Policy Robust 

Consider the toy Social Security policy introduced in the previous section with a finite 
termination time, T, 

Q = Ml - p{t')) - c out p{t')) e^"*'). (24) 

As we saw earlier, this policy is stable by design provided that p satisfies Eq. (21). In the 
previous section we also showed explicitly that the policy is not robust. In this section 
we show how the prescription in Section 6 allows us to find a robust extension of this toy 
model. 

Using that q = p for this model, we find from Eq. (19) that A is given by: 



dA 
~dt' 

The solution that satisfies the boundary condition A(T) = is 



j = -(c in + c out )e^ T - e \ (25) 



f e r(T-t') _ j\ 

A(t') = (c m + c out ) I J . (26) 

With these results we find the following robust extension of our original policy: 



Q = 



( 1 _ e -r(T-f ) \ 
C in (l - p{t')) - C out p(t') + (C in + C out ) P(t') 



3 r(T-f) 



(27) 



r 

To further simplify the discussion we take the limit r — > 0: 

Q = [Cj n (l - P (t')) - Coutpit') + (Cj n + c out ){T - t')p{t')] . (28) 
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Now we repeat the calculation of the real-world value of the policy from the previous 
section to see how the robust extension responds to forecasting errors. As before, the 
observed percentage of retirees is p = p + dp. For the policy in Eq. (28) we then find that, 

Q = (ci„ + c out )(-5p(t') + (T — t')5p(t')) = (c m + c out ) d{{T ( 29 ) 

This real-world cashflow integrates to V(T) = since 5p(0) = 0. This extension of our 
non-robust toy Social Security is manifestly robust. In fact is is super-robust because Q is 
linear in p in this example. More realistic, non-linear models will not have this property. 

Of course there are other ways to make a policy robust, for example by simply modifying 
the inflows to match the outflows. This yields the Pay-As- You-Go solution with Q = 
discussed in Section 4. 

It is informative to compare these two ways of constructing robust extensions of a non- 
robust starting point. Parametrize the robust extension as follows: 

Q = D(p,p, 0(1 - p(0) " «(*'), (30) 

where the second term is the payout term from the original policy to preserve the policy 
goal, and the first term is a modified pay-in term to make the policy robust. D is the 
amount working people have to pay in. It replaces the constant contribution Cj„ in the 
non-robust starting point. 

Using either the Q from Eq. 28 or Q = for the Pay-As- You-Go solution, we can now 
solve for D to find to leading order in dp 

D PG = c rn + te» + c «*) 2 Sp (31) 

Cout 

in the Pay- As- You-Go case and 

D R = c m + (Cm + C ° Mf) V - t')5p (32) 

Cout 

for the robust extension in Eq. (28). 

Dpc shows the disadvantages of the Pay- As- You-Go solution. If the number of retirees 
exceeds forecasts, i.e., bp > 0, the working population pays more. Conversely, if it is lower, 
they pay less. Pay-As- You-Go does not anticipate changes. It simply passes on the current 
cost of supporting the retirees to the working population. 

The detailed properties of Dr depend on how the robust extension is constructed, but 
even in our simple example, we can see how this robust policy anticipates change. At any 
point in time, the inflows are calculated based on how quickly reality diverges from the 
forecast, dp, and the remaining time to termination, T — t'. The policy extrapolates the 
current rate of divergence to the termination date, and adjusts the cash inflows based on 
this extrapolation. 

Both robust extensions have advantages and disadvantages. The Pay-As- You-Go solu- 
tion tends to be cyclical, because it raises rates when the situation becomes difficult. If 
the forecasting errors are small, this is a good solution, but if they are large, these policies 
can have a positive feedback loop. If Social Security contributions are too high relative to 
benefits, more people will retire as early as possible, driving up contributions even more. 
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The robust extension discussed in this section responds much faster because it depends 
on the rate of change of the forecasting error. As soon as reality diverges from the forecast, 
this policy responds by raising or lowering rates assuming that the current rate of divergence 
will continue. If this expectation is true, this robust extension spreads the cost of the 
forecasting error more evenly over time. However, if the forecasting error oscillates around 
zero or the divergence slows down, this policy overreacts and unduly penalizes payees early 
in the policy period. Nevertheless, this extension is less cyclical than the Pay-As- You-Go 
solution, because it raises rates as the divergence between forecast and reality accelerates 
and lowers rates as it slows down. Given that most public policies aim to smooth out the 
economic cycles, this is more desirable than the Pay-As- You-Go solution which tends to 
amplify these cycles. 

9 Concluding Remarks 

In this paper, we propose a framework to analyze how public policies respond to forecasting 
errors. We argue that good policy design should minimize sensitivity to forecasting errors, 
and derive constraints on policies that accomplish this. These constraints show that policies 
can only be insensitive to forecasting errors if their cashflows depend on parameter and their 
time derivatives. 

Model-independent results, like the constraints derived here, are useful because they can 
guide policy design. A designer can test a draft policy for robustness using the results in this 
paper. Conversely, the results can guide a policy designer, by indicating which ingredients 
must be present for a policy to be insensitive to forecasting errors. 

Most current policies are fully exposed to forecasting errors because they do not satisfy 
the constraints derived here. This may be part of the reason why Social Security, many 
defined benefit plans, and other entitlements run into financial problems. Policies designed 
to satisfy the constraints derived here have a feedback mechanism that allows them to adapt 
if reality unfolds differently than the policy designers anticipated. 

The methods developed in this paper should apply in other contexts where parameter- 
dependent cashflows play a role. Examples may include pension funds, business plans, and 
similar applications. 
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